Ownership, licences and stored work
Storage does not transfer ownership. Terms grant licences
Copyright in a photograph belongs to whoever made it, and uploading a file somewhere does not move it. What a storage provider’s terms of service do is grant that provider a licence — permission to do specific things with your files so that the service can function.
That licence is not optional and not, by itself, a warning sign. A service physically cannot store, copy between regions, generate a thumbnail or send a file to a browser without permission to copy and transmit it. The question worth asking is never is there a licence but what is the licence limited to.
Three limits are worth reading for, in any provider’s terms:
- Scope. Is the licence granted for operating and providing the service, or does it extend to improving, developing, promoting or training? Those extra verbs are where a hosting licence becomes something else.
- Duration. Does it end when you delete the file or close the account, or is it described as perpetual or irrevocable? A licence that survives deletion is describing something other than hosting.
- Sublicensing. Can the provider pass the licence on to affiliates, partners or successors? This is the clause that decides what an acquisition does to your archive.
This page is a reading guide, not legal advice, and it does not interpret any specific company’s terms — including PhotoLog’s. PhotoLog’s terms are the document that governs your account, and it is the one to read.
What PhotoLog’s architecture does with access
Beyond what any terms say, a key model decides who can open a file at all. PhotoLog’s is hierarchical: a studio has its own key, sealed to each of its members; each vault inside a studio has its own key wrapped under the studio’s; and each photo or video has its own key, generated once, never reused, wrapped under its vault’s current key.
The practical consequence for a working photographer is about removal. When someone is removed from a vault, its keys are rotated, so material added afterwards is protected by keys that person never held.
And here is the limit, stated where you will read it rather than in a footnote. Rotation protects what comes next. It does not reach backwards into anything already downloaded, screenshotted or synced to a device. The same is true of a share link: deactivating one stops further access through it, and does not undo what a holder already saw or saved. A compromised link is replaced, not repaired.
If that sounds obvious, it is worth saying anyway, because “revoke access” is routinely written as though it retrieves files. It does not, here or anywhere.
Delivering work to a client
A client gallery is a share, and a share link works like a key: whoever holds it can use it. Two practical consequences follow.
- Send it over a channel you would send a key over. A link forwarded into a group chat is a link the group has.
- Deactivate on a schedule, not on a suspicion. Because deactivation is forward-looking, its value is in limiting how long a link stays live, not in undoing a leak after the fact.
Client delivery covers the workflow itself.
Model training, and the honest limit of the assurance
PhotoLog does not run content analysis or model training over customer media — no machine-learning or image-recognition dependency appears in its dependency manifests, checked 2026-09-01. That is a statement about conduct and installed capability, evidenced negatively. No-AI storage explains what that kind of evidence does and does not establish, and gives four questions for testing the same claim against any provider.
What none of this settles is what happens outside a provider’s storage: a photograph published on a portfolio site, a social platform or a client’s own website is governed by that platform’s terms and by whatever crawls it, not by where the original is archived. Storage architecture answers a narrow question well. It does not answer that one at all.
What this page does not claim
- Not legal advice, and not an interpretation of anyone’s terms. The three limits above are things to read for. Whether a specific clause has a specific effect in your jurisdiction is a question for a lawyer.
- Not a claim that PhotoLog can prevent copying by someone who has legitimate access. Anyone who can see a photograph can capture it. Access control governs who can see it, and nothing more.
- Not a claim about what PhotoLog is unable to do. See how encryption works for the precise statement about where encryption happens and where the limits sit.
- Not a claim that removing a member deletes their copies. Key rotation protects future material. It has no reach over anything already downloaded.
How we verified this
Every statement above was checked against PhotoLog's own source and documentation on the date shown. Where the source did not settle a question, the page says so rather than filling the gap.
- Each studio has its own key sealed to its members; each vault inside a studio has its own key wrapped under the studio's key; each photo or video has its own key, generated once and never reused, wrapped under its vault's current key (verified 2026-09-01)
- A share link's key travels only inside the link, in the part of the address browsers do not send to any server (verified 2026-09-01)
- Revoking a share link stops future use of it, and does not undo what a holder already saw or saved with it beforehand (verified 2026-09-01)
- Whoever created a share link can deactivate it at any time, which stops new access through that link without touching photos or videos already added while it was active (verified 2026-09-01)
- No machine-learning, image-recognition or content-analysis dependency appears in PhotoLog's API dependency manifest (verified 2026-09-01)